| From ef6b1ce2b7ef239c36b3eef0423e4bbb709c1b4e Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Sun, 13 Sep 2020 09:52:30 -0700 |
| Subject: ALSA: asihpi: fix iounmap in error handler |
| |
| From: Tom Rix <trix@redhat.com> |
| |
| [ Upstream commit 472eb39103e885f302fd8fd6eff104fcf5503f1b ] |
| |
| clang static analysis flags this problem |
| hpioctl.c:513:7: warning: Branch condition evaluates to |
| a garbage value |
| if (pci.ap_mem_base[idx]) { |
| ^~~~~~~~~~~~~~~~~~~~ |
| |
| If there is a failure in the middle of the memory space loop, |
| only some of the memory spaces need to be cleaned up. |
| |
| At the error handler, idx holds the number of successful |
| memory spaces mapped. So rework the handler loop to use the |
| old idx. |
| |
| There is a second problem, the memory space loop conditionally |
| iomaps()/sets the mem_base so it is necessay to initize pci. |
| |
| Fixes: 719f82d3987a ("ALSA: Add support of AudioScience ASI boards") |
| Signed-off-by: Tom Rix <trix@redhat.com> |
| Link: https://lore.kernel.org/r/20200913165230.17166-1-trix@redhat.com |
| Signed-off-by: Takashi Iwai <tiwai@suse.de> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| sound/pci/asihpi/hpioctl.c | 4 ++-- |
| 1 file changed, 2 insertions(+), 2 deletions(-) |
| |
| diff --git a/sound/pci/asihpi/hpioctl.c b/sound/pci/asihpi/hpioctl.c |
| index 3ef9af53ef497..0d5ff00cdabca 100644 |
| --- a/sound/pci/asihpi/hpioctl.c |
| +++ b/sound/pci/asihpi/hpioctl.c |
| @@ -346,7 +346,7 @@ int asihpi_adapter_probe(struct pci_dev *pci_dev, |
| struct hpi_message hm; |
| struct hpi_response hr; |
| struct hpi_adapter adapter; |
| - struct hpi_pci pci; |
| + struct hpi_pci pci = { 0 }; |
| |
| memset(&adapter, 0, sizeof(adapter)); |
| |
| @@ -502,7 +502,7 @@ int asihpi_adapter_probe(struct pci_dev *pci_dev, |
| return 0; |
| |
| err: |
| - for (idx = 0; idx < HPI_MAX_ADAPTER_MEM_SPACES; idx++) { |
| + while (--idx >= 0) { |
| if (pci.ap_mem_base[idx]) { |
| iounmap(pci.ap_mem_base[idx]); |
| pci.ap_mem_base[idx] = NULL; |
| -- |
| 2.25.1 |
| |